Mercurial > hg > nginx
comparison src/mail/ngx_mail.h @ 5989:ec01b1d1fff1
Mail: client SSL certificates support.
The "ssl_verify_client", "ssl_verify_depth", "ssl_client_certificate",
"ssl_trusted_certificate", and "ssl_crl" directives introduced to control
SSL client certificate verification in mail proxy module.
If there is a certificate, detail of the certificate are passed to
the auth_http script configured via Auth-SSL-Verify, Auth-SSL-Subject,
Auth-SSL-Issuer, Auth-SSL-Serial, Auth-SSL-Fingerprint headers. If
the auth_http_pass_client_cert directive is set, client certificate
in PEM format will be passed in the Auth-SSL-Cert header (urlencoded).
If there is no required certificate provided during an SSL handshake
or certificate verification fails then a protocol-specific error is
returned after the SSL handshake and the connection is closed.
Based on previous work by Sven Peter, Franck Levionnois and Filipe Da Silva.
author | Maxim Dounin <mdounin@mdounin.ru> |
---|---|
date | Wed, 25 Feb 2015 17:48:05 +0300 |
parents | 04e43d03e153 |
children | fc99323a3d79 |
comparison
equal
deleted
inserted
replaced
5988:3b3f789655dc | 5989:ec01b1d1fff1 |
---|---|
334 ngx_mail_init_protocol_pt init_protocol; | 334 ngx_mail_init_protocol_pt init_protocol; |
335 ngx_mail_parse_command_pt parse_command; | 335 ngx_mail_parse_command_pt parse_command; |
336 ngx_mail_auth_state_pt auth_state; | 336 ngx_mail_auth_state_pt auth_state; |
337 | 337 |
338 ngx_str_t internal_server_error; | 338 ngx_str_t internal_server_error; |
339 ngx_str_t cert_error; | |
340 ngx_str_t no_cert; | |
339 }; | 341 }; |
340 | 342 |
341 | 343 |
342 typedef struct { | 344 typedef struct { |
343 ngx_mail_protocol_t *protocol; | 345 ngx_mail_protocol_t *protocol; |